<?php

require_once 'class/curl.php';
require_once 'common/GlobalDefine.php';

class JSSDK {
    private $appId;
    private $appSecret;

    public function __construct($appId, $appSecret) {
        $this->appId = $appId;
        $this->appSecret = $appSecret;
    }
    
    public function getSignPackage() {
        $jsapiTicket = $this->getJsApiTicket();
        
        //注意URL一定要动态获取，不能hardcode
        $protocol = (! empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off' || $_SERVER['SERVER_PORT'] == 443) ? "https://" : "http://";
        $url = "$protocol$_SERVER[HTTP_HOST]$_SERVER[REQUEST_URI]";
        
        $timestamp = time();
        $nonceStr = $this->createNonceStr();
        
        //这里参数的顺序要按照 key 值 ASCII 码升序排序
        $string = "jsapi_ticket=$jsapiTicket&noncestr=$nonceStr&timestamp=$timestamp&url=$url";
        
        $signature = sha1($string);
        
        $signPackage = array(
            "appId" => $this->appId,
            "nonceStr" => $nonceStr, 
            "timestamp" => $timestamp, 
            "url" => $url, 
            "signature" => $signature, 
            "rawString" => $string);

        return $signPackage;        
    }
    
    private function createNonceStr($length = 16) {
        $chars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
        $str = "";
        for ($i = 0; $i < $length; $i ++) {
            $str .= substr($chars, mt_rand(0, strlen($chars) - 1), 1);
        }
    
        return $str;
    }
    
    public function getJsApiTicket()
    {
        $filename="../Json/jsapi_ticket.json";
        $data = json_decode(file_get_contents($filename));
        if ($data->expire_time < time()) {
            $accessToken = $this->getAccessToken();
            $url = "https://api.weixin.qq.com/cgi-bin/ticket/getticket?type=jsapi&access_token=$accessToken";
            $res = json_decode(httpGet($url));
            $ticket = $res->ticket;
            if ($ticket) {
                $data->expire_time = time() + 7000;
                $data->jsapi_ticket = $ticket;
                $fp = fopen($filename, "w");
                fwrite($fp, json_encode($data));
                fclose($fp);
                insertSecureComment($data->jsapi_ticket, time(), "jsapi_ticket");
            }
        } else {
            $ticket = $data->jsapi_ticket;
        }
        return $ticket;
    }
    
    public function getAccessToken() {
        //access_token应该全局存储与更新，以下代码以写入到文件中做示例
        $filename="../Json/access_token.json";
        $data = json_decode(file_get_contents($filename));
        if ($data->expire_time < time()) {
            $url = "https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid=$this->appId&secret=$this->appSecret";
            $res = json_decode(httpGet($url));
            $access_token = $res->access_token;
            if ($access_token) {
                $data->expire_time = time() + 7000;
                $data->access_token = $access_token;
                insertSecureComment($data->access_token, time(), "access_token");
                $fp = fopen($filename, "w");
                fwrite($fp, json_encode($data));
                fclose($fp);
            }
        } else {
            $access_token = $data->access_token;
        }
        
        return $access_token;
    }
}